公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-25 20:01 UTC

ZeR020 / opencode-mem0

OpenCode plugin that gives coding agents persistent memory using local vector database

TypeScriptMIT★ 11 星标⑂ 2 复刻始于 2026年4月在 GitHub 上查看 ↗

ZeR020/opencode-mem0 的健康指数为 100 分中的 64 分,处于「中等」区间。 其得分最高的类别是Engineering Quality(77/100),最低的是Sustainability & Governance(48/100)。 最近一次更新在 2 天前。 近期的大部分工作由 1 位贡献者完成。

64
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

64
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

ZeR020个人账户
1 关注者5 个公开仓库始于 2021年7月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npmopencode-mem02.18.62,550235 天前opencodepluginmemoryvector-databaseaicoding-agentlocalstandalone

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

76良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 2 天前
6.2/36提交节奏 — 52 周中有 9 周有提交
18/18提交量 — 最近一年 457 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year457
human_commit_share0.97
days_since_last_push2
active_weeks_last_year9

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 20 个发布版本
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 2.1 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count20
latest_release_tagv2.18.6
releases_from_tags
days_since_latest_release5
mean_days_between_releases2.1
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

53中等 · 占总体的 18%
评分方式
16.2/60星标 — 11 个星标
0/25复刻 — 2 个复刻
0/15关注者 — 1 位关注者
所用输入
forks2
stars11
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
45.4/80月度下载量 — npm 合计每月 2,550 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesopencode-mem0
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,550
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

48存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
46.8/46.8议题解决 — 100% 的议题已关闭
17.1/38.3PR 接受 — 已裁定的 PR 中 21/47 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/29 approved changesets -- score normalized to 0
所用输入
merged_prs21
open_issues0
closed_issues5
issue_closed_ratio1
closed_unmerged_prs26
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
2.2/25所有者影响力 — ZeR020 有 1 位关注者
15.6/25既往记录 — 5 个公开仓库,账户约 4 年
所用输入
followers1
owner_typeUser
is_verified
owner_loginZeR020
public_repos5
account_age_days1,822
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 23 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesopencode-mem0
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

77良好 · 占总体的 20%

工程实践

68中等
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://github.com/ZeR020/opencode-mem0
10/10仓库描述
10/10主题标签 — 8 个主题标签
0/10Wiki
所用输入
topicsai, coding-agent, local-first, memory, opencode, plugin, sqlite, vector-database
has_wiki
homepagehttps://github.com/ZeR020/opencode-mem0
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

67中等 · 占总体的 16%

安全态势

63中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.2
已排除计分(无数据或不适用):branch_protection, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
8.5/25间接依赖不含已知公告 — 2 个受影响:adm-zip 0.5.18 (high 7.5), sharp 0.34.5 (high 7.3)
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories2
affected_packages2
assessed_packages158
unassessed_packages0
affected_by_severityhigh 2
direct_affected_packages0
比对的是 npm:opencode-mem0@2.18.6 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 158 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

53中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 97 次人类提交中有 97 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — tsconfig.json
10/10可复现环境 — devcontainer
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 3 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.03
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
55/55可控的文件大小 — 采样的 141 个源文件中有 0 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes55,224
source_files_sampled141
oversized_source_files0

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

11GitHub 星标
1贡献者
457最近 12 个月提交数
2距最近推送天数
20发布版本数
1巴士系数(bus factor)
0开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 2 ⇿
0Star
2Fork

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

111222212026-062026-062026-06
OpenSSF Scorecard 6.2 / 10
6.2综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-25 20:01 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
直接依赖 10
注册表软件包版本约束清单文件
npm@ai-sdk/anthropic^4.0.5package.json
npm@ai-sdk/openai^4.0.5package.json
npm@huggingface/transformers^4.2.0package.json
npm@opencode-ai/plugin^1.14.31package.json
npm@opencode-ai/sdk^1.14.31package.json
npmai^7.0.4package.json
npmbetter-sqlite3^12.1.0package.json
npmfranc-min^6.2.0package.json
npmusearch^2.25.1package.json
npmzod^4.4.1package.json
全部依赖 18

来自 GitHub 依赖图的完整解析依赖集合:10 个直接依赖与 8 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npm@ai-sdk/anthropic^4.0.5直接
npm@ai-sdk/openai^4.0.5直接
npm@huggingface/transformers^4.2.0直接
npm@opencode-ai/plugin^1.14.31直接
npm@opencode-ai/sdk^1.14.31直接
npmai^7.0.4直接
npmbetter-sqlite3^12.1.0直接
npmfranc-min^6.2.0直接
npmusearch^2.25.1直接
npmzod^4.4.1直接
npm@types/better-sqlite3^7.6.13间接
npm@types/bun^1.3.13间接
npm@vitest/coverage-v8^4.1.9间接
npmhusky^9.1.7间接
npmlint-staged^17.0.8间接
npmprettier^3.8.3间接
npmtypescript^7.0.2间接
npmvitest^4.1.9间接
依赖安全公告 2

安装 npm:opencode-mem0@2.18.6 会引入 158 个包(直接与传递):其中 2 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
adm-zip0.5.18间接10.6.0
sharp0.34.5间接10.35.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "ai",
        "coding-agent",
        "local-first",
        "memory",
        "opencode",
        "plugin",
        "sqlite",
        "vector-database"
      ],
      "is_fork": false,
      "size_kb": 1961,
      "has_wiki": false,
      "homepage": "https://github.com/ZeR020/opencode-mem0",
      "languages": {
        "CSS": 18467,
        "HTML": 1439,
        "Shell": 11863,
        "JavaScript": 60693,
        "TypeScript": 1054162
      },
      "pushed_at": "2026-07-23T03:06:35Z",
      "created_at": "2026-04-30T10:03:08Z",
      "owner_type": "User",
      "updated_at": "2026-07-19T20:24:15Z",
      "description": "OpenCode plugin that gives coding agents persistent memory using local vector database",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "ZeR020",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/88128532?v=4",
      "created_at": "2021-07-29T05:21:58Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 1822
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.18.6",
          "kind": "patch",
          "published_at": "2026-07-19T20:24:51Z"
        },
        {
          "tag": "v2.18.5",
          "kind": "patch",
          "published_at": "2026-07-19T20:01:49Z"
        },
        {
          "tag": "v2.18.4",
          "kind": "patch",
          "published_at": "2026-07-19T19:46:11Z"
        },
        {
          "tag": "v2.18.3",
          "kind": "patch",
          "published_at": "2026-07-04T09:50:52Z"
        },
        {
          "tag": "v2.18.2",
          "kind": "patch",
          "published_at": "2026-07-01T18:33:25Z"
        },
        {
          "tag": "v2.18.1",
          "kind": "patch",
          "published_at": "2026-07-01T13:20:28Z"
        },
        {
          "tag": "v2.18.0",
          "kind": "minor",
          "published_at": "2026-07-01T10:59:35Z"
        },
        {
          "tag": "v2.17.5",
          "kind": "patch",
          "published_at": "2026-06-30T19:57:48Z"
        },
        {
          "tag": "v2.17.4",
          "kind": "patch",
          "published_at": "2026-06-30T18:24:41Z"
        },
        {
          "tag": "v2.17.3",
          "kind": "patch",
          "published_at": "2026-06-30T17:56:30Z"
        },
        {
          "tag": "v2.17.2",
          "kind": "patch",
          "published_at": "2026-06-30T17:18:49Z"
        },
        {
          "tag": "v2.17.1",
          "kind": "patch",
          "published_at": "2026-06-28T17:10:42Z"
        },
        {
          "tag": "v2.17.0",
          "kind": "minor",
          "published_at": "2026-06-28T13:55:35Z"
        },
        {
          "tag": "v2.16.2",
          "kind": "patch",
          "published_at": "2026-05-29T11:32:41Z"
        },
        {
          "tag": "v2.16.1",
          "kind": "patch",
          "published_at": "2026-05-29T07:28:05Z"
        },
        {
          "tag": "v2.16",
          "kind": "other",
          "published_at": "2026-05-17T18:48:33Z"
        },
        {
          "tag": "v2.15.1",
          "kind": "patch",
          "published_at": "2026-05-06T20:12:22Z"
        },
        {
          "tag": "v2.15.0",
          "kind": "minor",
          "published_at": "2026-05-06T15:36:00Z"
        },
        {
          "tag": "v2.14.5",
          "kind": "patch",
          "published_at": "2026-05-06T11:51:51Z"
        },
        {
          "tag": "v2.14.4",
          "kind": "patch",
          "published_at": "2026-05-01T19:12:39Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e123d97946d590b87d5ca7c66f9615121d163996",
          "body": "…ws for DeepSource JS-0067\n\nThe v2.18.4 rewrite introduced two new top-level function declarations\n(normalizeParams, probeBackend) on top of the three pre-existing ones.\nDeepSource's diff-based JS quality gate flags newly-introduced top-level\nfunction declarations as blocking (JS-0067), which flippe\n[…]\ning top-level\nfunctions, flagged on e2ddb57 because that commit touched it) is out of\nthis commit's diff and not re-counted.\n\nGates: typecheck, build, 747 tests, prettier, deepsource lint — all green.",
          "is_bot": false,
          "headline": "fix(lint): convert sqlite-bootstrap top-level functions to const arro…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-19T20:24:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e2ddb578918ef76f64a70f045529f52d13a05c32",
          "body": "GitHub CodeQL flagged localStorage.setItem of the dashboard API key as\njs/clear-text-storage-of-sensitive-data (CWE-312/315). The alert is\ntechnically accurate on the pattern but the implied risk is not realizable\nunder the current threat model, so alert #8 was dismissed as false positive.\n\nAdded an\n[…]\nit trigger: if the dashboard is ever hosted non-loopback,\nmove to sessionStorage with short TTL or exchange the raw key for a\nnon-extractable comparison-only token.\n\nNo behavior change — comment only.",
          "is_bot": false,
          "headline": "docs(web): document threat-model rationale for CodeQL alert #8 dismissal",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-19T20:10:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c0bab045db412e92a450d7e32dc6e307d410a39",
          "body": "Dependabot PR #51 proposed bumping typescript from 5.9.3 to 7.0.2. The\nbare bump broke main's build in two places; landed here with the fixes:\n\n1. scripts/build.mjs: require.resolve(\"typescript/bin/tsc\") fails under\n   TS 7.0 because ./bin/tsc is no longer an importable subpath (the\n   exports map o\n[…]\nes field is set, breaking platform-server.ts with\n   TS2868 'Cannot find name Bun'. Added explicit types: [\"bun\"].\n\nGates on main with TS 7.0.2: typecheck, build, 747 tests, format, lint.\n\nCloses #51.",
          "is_bot": false,
          "headline": "chore(deps): bump typescript to 7.0.2 with build-tooling fixes (#51)",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-19T20:01:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0249d00fcce8397ff0ebefb012cdc1cf6de1935",
          "body": "…hes (#52)\n\nbetter-sqlite3@12 prebuilds target Node ABI 137 (Node 22); OpenCode v1.18.3\nbundles Node 24 (ABI 146), so the native .node failed to load with\nNODE_MODULE_VERSION 137 ... requires 146 and every memory op threw.\n\nsqlite-bootstrap now probes backends in ABI-safety order:\n  bun:sqlite -> no\n[…]\nnormalizes a single\nArray bind-arg into positional params for parity across all three backends\n(better-sqlite3 auto-unpacks; node:sqlite and bun:sqlite do not).\n\nReported by @Kingor-blip in issue #52.",
          "is_bot": false,
          "headline": "fix(sqlite): fall back to node:sqlite when better-sqlite3 ABI mismatc…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-19T19:45:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f51b0accf07ad63b032f3d1ea9df49283cee4984",
          "body": "…forces it\n\nThe CSP was duplicated: both an http-equiv meta tag in index.html and\nan HTTP header in _securityHeaders(). The meta tag triggered SonarCloud\nS7039 (unsafe-inline in style-src). Removing it eliminates the duplicate\nwhile the HTTP header continues to enforce the CSP on every response,\nincluding static files (serveStaticFile spreads _securityHeaders()).",
          "is_bot": false,
          "headline": "fix: remove redundant CSP meta tag from HTML — HTTP header already en…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-06T19:26:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67a2828541fc7636bbbb812d4e33f616d429de7c",
          "body": "…l dashboard\n\nAdd NOSONAR comment to CSP meta tag. style-src 'unsafe-inline' is\nintentional: the local-only dashboard uses dynamic inline styles\nextensively (DOMPurify, template literals with style= attributes).\nRemoving it would require a full refactor to external styles for all\ndynamic UI rendering. The CSP is defense-in-depth, not the primary\nsecurity boundary — the web server binds to localhost by default.",
          "is_bot": false,
          "headline": "fix: suppress S7039 on style-src unsafe-inline — intentional for loca…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-06T19:21:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19511cd7d2f4e34aa33874d03d4b10bd2522b2a0",
          "body": "…versal\n\n- Remove 'unsafe-inline' from script-src CSP: extract inline theme\n  bootstrap script to external theme-bootstrap.js, register in static\n  file map. style-src retains 'unsafe-inline' for dynamic inline styles.\n- Inline path containment guard in createTranscriptsDb so SonarCloud\n  taint analysis (tssecurity:S8707) can trace sanitization at the\n  mkdirSync sink, not just at the CLI entry point.\n- Update CSP assertions in web-server tests.",
          "is_bot": false,
          "headline": "fix: resolve SonarCloud quality gate — CSP unsafe-inline and path tra…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-06T19:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8a0aace194650da47fb42e37094dac484fd2f1c",
          "body": "- Parameterize value in user-prompt-manager markMultiple() to prevent\n  latent SQL injection (field still interpolated as column name by design)\n- Escape LIKE wildcards (%, _) in vector-search FTS5 fallback query\n- Strip quotes from sessionID before FTS5 MATCH interpolation\n- Normalize parameterized route paths in rate limit bucket keys to\n  prevent unbounded Map growth from unique memory/conflict/prompt IDs\n- Use crypto.timingSafeEqual for web server API key comparison",
          "is_bot": false,
          "headline": "fix: harden SQL/FTS5/LIKE injection, rate limit leak, and API key timing",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-06T14:18:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53970454f78c4b005a97b7340486431b86c62b80",
          "body": "Electron added a 200 MB bundled Chromium binary to get a native window\ninstead of a browser tab. The plugin already runs a local web server\nat 127.0.0.1:4747 serving the rebuilt SPA — that IS the dashboard.\nElectron was over-engineering for a plugin that already has a web UI.\n\nRemoved:\n- src/electro\n[…]\ns,\ni18n cleanup, bug fixes) remains — that was the actual value.\n\nponytail: should have questioned the premise at rung 1 ('does this need\nto exist?') instead of treating 'in electron' as a constraint.",
          "is_bot": false,
          "headline": "revert: remove Electron desktop wrapper — web dashboard is sufficient",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-04T11:43:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29d95e978bce1d194d5ab07f68675a8287f14b1e",
          "body": "- CHANGELOG.md: add [Unreleased] entry covering the Electron desktop\n  dashboard, SPA redesign, i18n cleanup, and bug fixes (profile API\n  shape, duplicate keys, non-string ID slicing)\n- ARCHITECTURE.md: add src/electron/ to directory structure, update\n  WebServer description to mention Electron wra\n[…]\n to reflect the new SPA\n- README.md: mention Electron desktop app option in Key Features\n\nDOX AGENTS.md files (root, src/, src/web/, src/electron/) updated\nlocally but gitignored per project contract.",
          "is_bot": false,
          "headline": "docs: update changelog, architecture, and README for Electron dashboard",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-04T11:38:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2b9ed3791e9c456dbf002feca726c0bf20aa4fd",
          "body": "…tive design\n\nReplace the legacy Memory Explorer SPA with a complete rebuild:\n\n- Add Electron desktop wrapper (src/electron/main.ts, preload.ts) that\n  reuses the existing WebServer + REST API, initializes config and warms\n  up the memory client before loading the dashboard in a BrowserWindow\n- Rewr\n[…]\n to fetch the\n  binary, plus electron and electron:dev scripts\n\nNet -1885 lines across the web UI. All quality gates pass: typecheck,\nbuild, 738 tests, prettier, deepsource lint, bun audit (no vulns).",
          "is_bot": false,
          "headline": "feat(web): rebuild dashboard as Electron desktop app with terminal-na…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-04T11:36:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a65fedf2d7d96ba241e69bdf58e21bb103c1329",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v2.18.3",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-04T09:49:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "670968cb29bb7c096de3a115c404563527813d24",
          "body": "Bumps [@ai-sdk/anthropic](https://github.com/vercel/ai/tree/HEAD/packages/anthropic) from 3.0.92 to 4.0.5.\n- [Release notes](https://github.com/vercel/ai/releases)\n- [Changelog](https://github.com/vercel/ai/blob/main/packages/anthropic/CHANGELOG.md)\n- [Commits](https://github.com/vercel/ai/commits/@\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @ai-sdk/anthropic from 3.0.92 to 4.0.5 (#50)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-04T09:47:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "789021076fdc8e7f145df6d938e7f96f93773892",
          "body": "Honor explicit zero values from stored memory rows when applying lifecycle decay and merging conflict resolutions. This prevents memories with decay_rate 0 or zeroed scoring metadata from being silently defaulted to non-zero values.\n\nRemove two dead skipped tests: an empty contextTracker-era test and a skipped user learning assertion that only checked that the function existed.",
          "is_bot": false,
          "headline": "fix(memory): preserve zero-valued decay metadata",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T20:37:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7c750d4d853564c0402af8a1eea10b02518da8f",
          "body": "Remove the unused iso-639-3 dependency by canonicalizing franc-min ISO-639-3 results with Intl APIs. Preserve the explicit language fallback map, add regression coverage for German detection, and verify the dependency behavior with opensrc source inspection.\n\nHonor explicit zero values for retrieval\n[…]\neval.diversityThreshold by using nullish defaults. Add regression tests for both paths.\n\nForce patched transitive dependency versions through package overrides so bun audit reports no vulnerabilities.",
          "is_bot": false,
          "headline": "fix(retrieval): honor zero-valued config",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T20:20:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a36c8be5da9994e1c240d1303d2ea36117daf01",
          "body": null,
          "is_bot": false,
          "headline": "feat(profile): apply confidence decay on session idle",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:21:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91cdced4f2f8d0a4f30bad2b9ffb30a08a945131",
          "body": null,
          "is_bot": false,
          "headline": "test: update API handler tests for Topics: tag embedding template",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:20:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e78cb3239aa5c89beb37e7ffa71bdff3353f39f",
          "body": "…ulation\n\nUser profile preferences, patterns, and workflows now decay at 1%/day\n(~37% per month). Items below 0.1 confidence are removed. Decay is\nidempotent (tracked via lastDecayApplied), runs before merging new\nobservations and on profile refresh. Generated preferences are\nnormalized with lastUpdated timestamps.",
          "is_bot": false,
          "headline": "feat(profile): add confidence decay to prevent stale preference accum…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e4b889133a59c4177bbad26d6218aa8bce5f717",
          "body": "…tity\n\nAdd .opencode-mem-project marker file support: when present in any parent\ndirectory, all sessions under it share one project memory store instead of\nsplitting by git repo. Enables multi-repo workspaces (e.g. Google repo tool,\nmonorepos with nested git repos) to share a single project-wide memory store.",
          "is_bot": false,
          "headline": "feat(tags): support workspace marker file for multi-repo project iden…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:20:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1c5298e319a126ddfd32cf1cc54cbd9258e2c07",
          "body": "Third-party plugins can now import canonical container-tag helpers\n(getProjectTagInfo, getUserTagInfo, getTags) via the ./tags subpath\nto write into the same memory store without reverse-engineering tag conventions.",
          "is_bot": false,
          "headline": "feat(api): export tag helpers via ./tags subpath for third-party plugins",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a35ba07c5093ad55ff6b6f2493915b1ba59e38f5",
          "body": "Node.js server shutdown now calls closeAllConnections() before close(),\nenables reuseAddr, and sets keep-alive timeouts to prevent CLOSE_WAIT\nsocket accumulation and port rebinding failures.",
          "is_bot": false,
          "headline": "fix(server): clean up sockets on shutdown to prevent port conflicts",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:20:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dd4e684d767bdaab9c4ba368c4d19dfe0fc0d9c",
          "body": "The memory timeline now shows both project-scope and user-scope memories\nwhen no specific project tag is selected, instead of only project memories.",
          "is_bot": false,
          "headline": "fix(web): include user-scope memories in web UI listing",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:20:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c147235de68a67183a044c5d4d6360bf9177077",
          "body": "… attempt tracking\n\nTransient LLM failures no longer silently lose conversation summaries.\nAuto-capture now retries with 2s/4s/8s exponential backoff, tracks\ncapture_attempts in the user_prompts table across restarts, and surfaces\nerror toasts only after the retry budget (default 3) is exhausted.\nIntentional skips remain silent.",
          "is_bot": false,
          "headline": "feat(auto-capture): add retry with exponential backoff and persistent…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:19:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5253469137311ca939def30d4db0812955953755",
          "body": "… JSON parse resilience\n\nWrap tag embeddings with a 'Topics:' prefix to match the multilingual-e5\ntraining distribution, producing more discriminative tag vectors. Add\nextractFirstJSON() bracket-matching helper to salvage valid JSON from\ncontaminated LLM tool call arguments (commentary after JSON, JS expressions),\nused across all three AI providers.",
          "is_bot": false,
          "headline": "feat(search): improve tag embedding quality with Topics: template and…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T19:19:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b08acf6ec2075ce65261814287c8c9a34dfa2a5",
          "body": null,
          "is_bot": false,
          "headline": "release: v2.18.2",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T18:31:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39cbddcf1d7423c941ad1d9b229bcd156f59bc31",
          "body": "Doubt-driven review found that removing ?? 0.92 entirely leaves threshold as\nundefined if CONFIG is partially mocked in test environments, silently disabling\ndedup (similarity >= undefined evaluates to false). Restoring the fallback but\naligned to the canonical config default 0.9 (not the original 0.92 which\ndisagreed with config.ts).",
          "is_bot": false,
          "headline": "fix(dedup): restore threshold fallback aligned to config default 0.9",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T18:24:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1bfd5531a3205ec30ce9031d7ab97f32d187386",
          "body": "… shared jaccardSimilarity\n\nDoubt-driven review found checkNegationOverlap used the wider NEGATION_PATTERNS\narray (5 patterns) instead of the original combined regex, stripping words like\n'discussion', 'distribution', 'union', 'false', 'incorrect' that the original\nnever touched. This changed interf\n[…]\nnsolidation; the original\ninline implementations all used the zero-alloc pattern.\n\nBoth issues found by retroactive code-review-and-quality + doubt-driven-development\nskill passes on the audit commit.",
          "is_bot": false,
          "headline": "fix(scoring): revert checkNegationOverlap to original regex, optimize…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T18:20:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2373a15b980e9d76d70bbf83e8330e68ac9e5d7e",
          "body": "…plication, fix perf\n\nDead code removed:\n- getProfileById (zero callers, user-profile-manager.ts)\n- 5 dead CSS badge classes for non-existent memory types (styles.css)\n\nDuplication consolidated:\n- 3 divergent jaccardSimilarity implementations unified to shared\n  text-analysis.ts export (vector-searc\n[…]\n\n- Dedup threshold ?? 0.92 fallback aligned to config default 0.9\n\nNet: -159 lines (11 files, 159 insertions, 318 deletions)\nVerification: typecheck, 729 tests, build, format, deepsource lint all pass",
          "is_bot": false,
          "headline": "refactor: repo-wide ponytail audit — remove dead code, consolidate du…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T18:13:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9edddc017fb064b7866a4c037a8ddac290e030b",
          "body": "…y symbols\n\nDelete closeShardManager() — truly dead function with zero references\nacross src, tests, and scripts. The shutdown handler already calls\nmemoryClient.close() → connectionManager.closeAll().\n\nRemove unnecessary export keyword from 17 runtime symbols used only\nwithin their own files: Shard\n[…]\nATIONS, MAX_LIST_MEMORIES,\nMAX_TIMELINE_ITEMS, getGitEmail, getGitName, getGitRepoUrl,\ngetGitCommonDir, getGitTopLevel, getProjectRoot, getProjectIdentity,\ngetUserProfileManager, getUserPromptManager.",
          "is_bot": false,
          "headline": "refactor: remove dead closeShardManager and un-export 17 internal-onl…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T17:40:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2c40be60773ebe0b5e2f46b522fbc25642ec2b2",
          "body": "Add portsAttributes for forwarded port 4096 (opencode web) with\nonAutoForward: openBrowser, and silence other ports.",
          "is_bot": false,
          "headline": "chore(devcontainer): label port 4096 and auto-open in browser",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T15:22:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "996b26a88306ec3fa1456d9427b82ed623ed5c57",
          "body": "The transcripts tab showed only a session ID, first 3 messages, then\n'...N more...' with no way to expand — no search, no filtering, no\ndetail view. Removed the UI only; backend TranscriptManager and\n/api/transcripts/search route remain (load-bearing for capture pipeline).",
          "is_bot": false,
          "headline": "fix(web): remove useless transcripts UI section",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T15:22:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21b9a3a969fa1ebc875cddefaf99df252c0557af",
          "body": "Dark/light theme toggle, transcript preview fix, radar chart fix,\nand web performance improvements (defer scripts, parallelized API\ncalls, favicon optimization, i18n RegExp elimination).",
          "is_bot": false,
          "headline": "chore(release): bump version to 2.18.1",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T13:19:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb5b9a8ea895d7d7dd3efac4cd4c7ef79f39eee5",
          "body": "…icon, eliminate RegExp in i18n\n\nPerformance fixes from web audit (4 safe, high-impact changes):\n\n1. Add defer to all 5 head scripts (lucide, marked, dompurify,\n   jsonrepair, i18n). Browser now renders the HTML shell immediately\n   while scripts parse in the background. Inline theme-prevention\n   s\n[…]\ntion with no visible quality loss\n   at favicon display sizes.\n\n4. Replace new RegExp() in i18n t() with string split/join. Eliminates\n   per-call RegExp object allocation in the translation hot path.",
          "is_bot": false,
          "headline": "perf(web): defer head scripts, parallelize init API calls, shrink fav…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T11:39:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ab93a859e0079982c4db96e0f9485225865971d",
          "body": "… and theme support\n\nTranscripts: message content lives in parts[].text (OpenCode session\nformat), not m.content. The render function was checking m.content as\na string, which was always undefined — every transcript showed only\n'...' placeholders. Now extracts text from parts[], shows tool calls\nas \n[…]\nhex colors\n(#9a9898, #646262, #007aff) replaced with CSS custom properties\n(var(--ash), var(--mute), var(--accent)) so the chart adapts to dark\nmode. Added description explaining what the chart shows.",
          "is_bot": false,
          "headline": "fix(web): transcript previews show actual content, radar chart labels…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T11:23:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a8b3bd1c07507ab8094f6a435f59ef6cdc19c78",
          "body": "- styles.css: [data-theme='dark'] token overrides + @media\n  prefers-color-scheme auto-detection. Dark theme remaps all color\n  tokens: canvas becomes #1a1818, ink inverts to #fdfcfc, accent\n  brightens to #0a84ff for dark contrast. Spacing/radius/typography\n  tokens unchanged.\n- index.html: theme-t\n[…]\ne first paint.\n- app.js: toggleTheme() cycles light↔dark, persists to\n  localStorage('mem0-theme'). initTheme() restores saved preference\n  or falls back to system @media query. Icon updates sun↔moon.",
          "is_bot": false,
          "headline": "feat(web): add dark/light theme toggle with system preference detection",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T11:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57ed4920e6ad69bfb5f7b2bd2babeecc9d8d8989",
          "body": "Web UI redesign with OpenCode manpage design system.",
          "is_bot": false,
          "headline": "chore(release): bump version to 2.18.0",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T10:58:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ebce4514e86d62ac4b5e546211aaec5654c200",
          "body": "Complete visual redesign of the Memory Explorer Web UI:\n\n- styles.css: full rewrite with DESIGN.md token system (CSS custom\n  properties for colors, spacing, radius, typography). Warm cream canvas\n  (#fdfcfc), near-black ink (#201d1d), JetBrains Mono / Berkeley Mono font\n  stack, 4px radius on inter\n[…]\nrings (en + zh) replaced with [+] bracket\n  markers. No ASCII box-drawing chars remain.\n- src/web/AGENTS.md: updated ownership and local contracts to document\n  the design system and token convention.",
          "is_bot": false,
          "headline": "feat(web): rebuild dashboard with OpenCode manpage design system",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T10:57:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12c17913bf9fd91ca131592432fb9f9d5fbc91d7",
          "body": "migrate() called createTranscriptsDb() unconditionally, so running the\nv1→v2 migration script with no args on a machine with no upstream data\nmkdir'd ~/.opencode-mem/data and created an empty transcripts.db orphan.\nNow only creates transcripts.db when result.databases > 0 — i.e. when\nreal v1 databases were found and upgraded. Also corrects the misleading\n'no (already exists)' report to 'skipped (no v1 databases found)'.",
          "is_bot": false,
          "headline": "fix(scripts): gate transcripts.db creation behind v1 database detection",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-07-01T10:36:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ccf1890a27f86f7b79592e0fd8ae9bfa5d17960",
          "body": "…eded\n\nThe truncation broke the expectation that auto-capture processes the\nfull conversation. Reverted buildMarkdownContext to send all AI\nresponses in full. The 413 TPM issue is a model-tier limitation, not\na code problem — users should choose a model with adequate TPM.",
          "is_bot": false,
          "headline": "revert: remove auto-capture context truncation — full AI responses ne…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T20:27:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d1c6e5fecec2e2e2ff7e6b4111ce968026faed7",
          "body": "…mits\n\nAuto-capture concatenated all AI responses, the full user prompt,\ntool calls, and latest memory into a single context string sent to the\nLLM summarizer with no size limit. On long sessions this produced\n16k-24k token payloads that exceeded free-tier TPM ceilings (e.g.\nGroq's 8k TPM on qwen3.6\n[…]\nbuildMarkdownContext. The user prompt and tool calls are kept in full;\nAI responses (the bulk) are truncated from the front, keeping the most\nrecent responses that are most relevant for summarization.",
          "is_bot": false,
          "headline": "fix(auto-capture): truncate context payload to stay within LLM TPM li…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T20:25:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b24381a7ed0735af2cfebddb4efe64608c9a61e",
          "body": "…build tools needed for most users\n\nThe previous guide listed Visual Studio Build Tools + Python as\nprerequisites, but better-sqlite3 ships prebuilt .node binaries for\nWindows x64 via prebuild-install. Build tools are only needed as a\nfallback for edge cases (Windows ARM64, very new Node versions) where\nno prebuilt binary exists — moved to troubleshooting section.",
          "is_bot": false,
          "headline": "docs: fix Windows setup — better-sqlite3 ships prebuilt binaries, no …",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T20:15:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17c41c6761159e2b829287b3aceabfa161db3a39",
          "body": "- Windows-specific prerequisites (Node.js, VS Build Tools for\n  better-sqlite3 native compile, Python 3 for node-gyp)\n- Windows config/data paths using %USERPROFILE% instead of ~\n- Troubleshooting table for common Windows + cross-platform issues\n- First Run section documenting the ~547MB embedding model download\n  and caching behavior (all platforms)",
          "is_bot": false,
          "headline": "docs: add Windows setup guide and first-run expectations to README",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T20:11:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24d3a3acfc7241fc0256e3d6c506800cb80d17ae",
          "body": null,
          "is_bot": false,
          "headline": "release: v2.17.5",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T19:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de9acdbf5ed5ea660e00cb7e94d1606d619f1de2",
          "body": "…fully\n\napp.js called marked.setOptions() at top-level script execution and\nlucide.createIcons() inside renderMemories/DOMContentLoaded. If any\nvendored library failed to load (missing file, stale dist build, path\nissue), the ReferenceError killed the entire script: no functions\ndefined, no event ha\n[…]\nryClient.addMemory, deleting ~45 lines of duplicated orchestration)\n- checkContradictionHeuristic missed substitution-based contradictions\n  ('instead of', 'replaced by') — added SUBSTITUTION_PATTERNS",
          "is_bot": false,
          "headline": "fix(web): guard vendor library calls so missing script degrades grace…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T19:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9107d1396dedbcb0778e8d6273699a19aaee5ae6",
          "body": "v2.17.1 added a restrictive CSP (default-src 'self') but index.html still\nloaded lucide/marked/dompurify/jsonrepair from CDN, so the UI crashed with\nReferenceError: marked is not defined (showed 'Total: 0' while the API\nserved correct data).\n\nVendored the four libraries into src/web/vendor/ with pin\n[…]\n suggested CSP relaxation (allowlisting\nunpkg.com/cdn.jsdelivr.net): it would reintroduce untrusted supply-chain\ncode execution without SRI and an outbound call on every UI load.\n\nReported by @ovizii.",
          "is_bot": false,
          "headline": "fix(web): vendor JS deps locally to unblock strict CSP, fixes #47",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T18:23:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e45be1b9dd5ac95d09e39229dad2e5151de4225c",
          "body": "…ConfidenceDecayDays config\n\n- README 'Auto-Capture' Key Feature: 'strips secrets and PII' → accurate\n  '<private> tag redaction' description (privacy.ts only redacts\n  <private>...</private> XML tags, does not detect raw secrets/PII)\n- Remove dead userProfileConfidenceDecayDays from config.ts (inte\n[…]\nEADME.md, docs/CONFIGURATION.md\n- Remove stale 'confidence decay' refs from docs/ARCHITECTURE.md\n  (applyConfidenceDecay was deleted in v2.17.2, zero production readers)\n- Bump version 2.17.2 → 2.17.3",
          "is_bot": false,
          "headline": "fix: correct README privacy overstatement and remove dead userProfile…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T17:55:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9c9466c093d376b4c7363874c0cda01e619113e",
          "body": "The injection.queryAwareFiltering config field was removed in v2.17.2\n(never read by any production code). The README config table was missed\nin that cleanup pass.",
          "is_bot": false,
          "headline": "docs: remove stale queryAwareFiltering config row from README",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T17:23:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44ccb90f7ec443611679cea5fa696c63323e9152",
          "body": "@boyxil and @bob56621517 were credited for issues #34/#35, which shipped\nin v2.17.0/v2.17.1 — not this release. Per AGENTS.md, contributors are\ncredited for the release that ships their contribution.",
          "is_bot": false,
          "headline": "fix: remove incorrectly carried-forward contributor credits from v2.17.2",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T17:20:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7fd67aa8f5153451a43d898320b2b7c12d167ac",
          "body": "Patch release: transcript capture independence, Node 22 ESM fix,\nSQL ESCAPE bug fix, release workflow changelog extraction fix,\ntwo rounds of dead-code ponytail-audit (-400 lines net),\nDeepSource remediation, minimal Codespace devcontainer.",
          "is_bot": false,
          "headline": "release: v2.17.2",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T17:17:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8329b4cb3581851d193c21c6d796683f371ae6d",
          "body": "Removed 13 verified-dead symbols across 35 files (-300 lines net). All\ndeletions were grep-verified and cross-checked with the codebase-memory\ncall graph (trace_path inbound -> [] for zero production callers). The\ntest-fake trap was applied: methods whose only callers were test doubles\nwere removed \n[…]\nared.ts\n\nAudit false positive corrected:\n- src/types/usearch.d.ts retained (load-bearing ambient module declaration)\n\nVerification: typecheck, 723 tests, build, format:check, lint-deepsource all pass.",
          "is_bot": false,
          "headline": "refactor: remove dead code and deduplicate from repo-wide ponytail-audit",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T15:46:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "83229247f5083c83ee9f8142f97304b91bc3100e",
          "body": "…ant types\n\nJS-W1041 (complex boolean return):\n- openai-chat-completion.ts: hasNonEmptyChoices type guard — collapsed\n  if(x) return false; return true pattern into direct boolean return\n\nJS-0331 (explicit type declarations on trivially-inferable defaults):\n- client.ts: private isInitialized: boolea\n[…]\nema.ts shouldSkipMigration: guard-clause pattern is clearer\n  than a complex boolean expression for migration skip logic\n\nVerified: typecheck (0 errors), 730 tests pass, build, format:check all clean.",
          "is_bot": false,
          "headline": "fix: DeepSource recommended — simplify boolean returns, remove redund…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T13:30:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35df08eb1f73c5fe01844cce125be4454f8e1507",
          "body": "Removed verified-dead code (confirmed via tsc --noUnusedLocals --noUnusedParameters\nand grep cross-check, tests excluded per .deepsource.toml):\n\nDead imports removed:\n- api-handlers.ts: safeToISOString (unused)\n- client.ts: SearchResult type, safeToISOString+safeJSONParse (both unused)\n- admin.ts: S\n[…]\neepSource web UI does not flag this.\n\nVerified: typecheck (0 errors), 730 tests pass, build, format:check all clean.\ntsc --noUnusedLocals --noUnusedParameters confirms 0 real issues remaining in src/.",
          "is_bot": false,
          "headline": "fix: remove dead code flagged by JS-0356 (unused TypeScript variables)",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T13:20:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6262f73fa3c28b6fe15ec8e3ee587ae9cde5df86",
          "body": "…tations\n\n- fix(vector-search): template literal `ESCAPE '\\'` produced empty escape char\n  (ESCAPE '') causing SQLite 'ESCAPE expression must be a single character'\n  errors in the getMemoriesBySessionID LIKE fallback path. Fixed to `ESCAPE '\\\\'`\n  which produces a valid single-backslash escape char\n[…]\n->const for conversationId (never reassigned)\n- fix(scoring): shorthand property totalUpdated (JS-0240)\n\nVerified: typecheck (0 errors), 730 tests pass, build, format:check,\nlint-deepsource all clean.",
          "is_bot": false,
          "headline": "fix: DeepSource audit — latent SQL ESCAPE bug, dead code, skipcq anno…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T13:06:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0683461472fba02cf0024e07e4fd56a104d5a55a",
          "body": "…late dedup\n\nDead code removed (graph-confirmed zero callers):\n- ensureShardTables, getShardByPath (shard-manager.ts)\n- countVectors(containerTag) (vector-search.ts)\n- getMessagesByRoleStmt prepared statement + field (ai-session-manager.ts)\n- maxProfileItems config field + docs + test ref\n- 6 duplic\n[…]\n (marked v8+)\n- Broken lint-deepsource.sh rules #1 (awk) and #10 (complexity) fixed\n\n22 files changed, net -92 lines (-434/+342)\nAll 730 tests + typecheck + build + format:check + lint-deepsource pass",
          "is_bot": false,
          "headline": "refactor: ponytail-audit — dead code, zod validator, provider boilerp…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-30T12:43:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6092f46af59d4e9d962f42de7cb7fbbd5db6425c",
          "body": null,
          "is_bot": false,
          "headline": "ci: add minimal devcontainer for codespace creation",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-29T11:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ae6dc939712f0e5085147b8701993f55aa117c7",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove .devcontainer setup — user will create codespace manually",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-29T11:42:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7a85ab329d449e58c298ebc13c8648b4d547153",
          "body": "…server and timeline fixes\n\nTranscript capture independence:\n- performTranscriptCapture now runs on session idle independently of\n  auto-capture (no longer gated by autoCaptureEnabled)\n- New test: tests/transcript-idle-wiring.test.ts verifies session.idle\n  triggers transcript capture when transcrip\n[…]\nwas orphaned in\n  linkedPairs and filtered out by Boolean(p.memory && p.prompt))\n\nCleanup:\n- Removed stale graphify-out entries from .gitignore\n- Updated ARCHITECTURE.md transcript capture description",
          "is_bot": false,
          "headline": "feat: transcript capture on session idle, structured output fix, web …",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-29T10:47:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "949c949d5acfd1ab243920da7ddb0d8627e1dc5a",
          "body": "Node 22's ESM loader requires 'with { type: \"json\" }' on JSON module imports.\nWithout it, importing dist/plugin.js throws ERR_IMPORT_ATTRIBUTE_MISSING.\nSince opencode runs under Node (installed via npm), it catches this error and\nsilently skips loading the plugin — opencode-mem0 was never active in \n[…]\n add the import attribute to the package.json import in src/plugin.ts.\nVerified: node --input-type=module -e 'await import(\"./dist/plugin.js\")'\nnow succeeds and exports OpenCodeMemPlugin, default, id.",
          "is_bot": false,
          "headline": "fix: add JSON import attribute for Node 22 compatibility",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-29T10:07:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99211ea3eb916d0e5ab7e2bbb87bba46ffd7946d",
          "body": "postCreateCommand was timing out during the JupyterLab pip install (slow —\ninstalls the full jupyter stack), killing setup.sh before bun run build could\nrun. Result: toolchain installed and deps fetched (210 packages) but no\ndist/plugin.js — the plugin was never built.\n\nMove JupyterLab install to th\n[…]\n JupyterLab is\nnice-to-have for the Codespaces UI button; the plugin build is load-bearing.\nAlso made the pip install non-fatal (|| echo) so a timeout there doesn't\nprevent the setup-complete message.",
          "is_bot": false,
          "headline": "fix(ci): reorder setup.sh — build plugin before slow JupyterLab install",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T20:29:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4d98bd24fe3a6c0d96548142a49dabed0693386",
          "body": "The ghcr.io/devcontainers/features/python:1 feature catastrophically conflicted\nwith the typescript-node:22 base image — it wiped /usr/local/share/nvm (node\ngone), didn't install its own python, and setup.sh failed immediately (no bun).\nResult: empty toolchain, no build, recovery-mode-equivalent sta\n[…]\n not disposable test VMs).\nThis puts jupyter + jupyter-lab in /usr/local/bin where Codespaces finds them,\nand jupyter_core importable from system Python — which pipx's isolated venv\nfailed to provide.",
          "is_bot": false,
          "headline": "fix(ci): revert python feature, install JupyterLab via system pip",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T20:26:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b3e993bda0e84a86c8c3df130ed07b997b5dc2",
          "body": "The manual pipx install of jupyterlab created an isolated venv where jupyter_core\nwas not importable from system Python and no plain 'jupyter' umbrella binary\nexisted. Codespaces' JupyterLab integration needs the full jupyter stack\naccessible, not just jupyter-lab in a venv.\n\nSwitch to the official \n[…]\n_core,\njupyter server, notebook, jupyterlab) into the system Python correctly.\nRemove the manual pipx jupyterlab lines from setup.sh; keep build-essential +\npkg-config for the native-module toolchain.",
          "is_bot": false,
          "headline": "fix(ci): install JupyterLab via devcontainer python feature",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T20:21:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f98680c54f3706ee82bf1c6fb9af62d0d734a2f2",
          "body": "The Codespaces 'Open in JupyterLab' button requires JupyterLab in the container.\nThe typescript-node:22 base image has python3 but no pip or JupyterLab.\n\nInstall via pipx (PEP 668 compliant for externally-managed Python on Debian):\n- apt install python3-pip pipx\n- pipx install jupyterlab\n- symlink jupyter-lab binaries to /usr/local/bin so non-login shells find them",
          "is_bot": false,
          "headline": "feat(ci): install JupyterLab in codespace test VM",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T20:15:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f92577d6da20ae48db2e46272126d00c1fa4a1a",
          "body": "The OMP ssh tool and postCreateCommand use non-login shells that don't source\n.profile/.bashrc, so bun (installed to ~/.bun/bin) was not on PATH. A symlink\ninto /usr/local/bin (default PATH for all shells) eliminates the need for a\nPATH export on every ssh call. Replaces the .profile PATH line, which was\nredundant with the bun installer's own .bashrc entry.",
          "is_bot": false,
          "headline": "fix(ci): symlink bun into /usr/local/bin for non-login shell PATH",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T20:06:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57d5aba332f6cc4bfc5d851c0c9091faf1dfce47",
          "body": "The opencode curl installer (https://opencode.ai/install) silently failed in\nthe non-interactive postCreateCommand context — it created ~/.opencode/bin/\nbut placed no binary there, and added no PATH line to .bashrc. Result: opencode\nwas installed (dist built, deps installed) but not executable after\n[…]\nve\ncontexts and lands in the npm global bin already on PATH for the\ntypescript-node:22 base image. Simplify PATH persistence to only bun (.profile),\nsince opencode no longer needs a custom PATH entry.",
          "is_bot": false,
          "headline": "fix(ci): install opencode via npm instead of curl installer",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T19:50:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cbbc9008e1fe7ec4bacd471f3df58f14b82cb35",
          "body": "The opencode installer places the binary in ~/.opencode/bin, not\n~/.local/bin. The runtime export and the persisted PATH_LINE both pointed at\n~/.local/bin, so opencode was not on PATH for login or non-interactive shells\neven though it was installed. Fixed both to use ~/.opencode/bin.",
          "is_bot": false,
          "headline": "fix(ci): correct opencode PATH to ~/.opencode/bin in setup.sh",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T19:47:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c362d781e75ded11ea409af8e4bfcad0b6b16ef",
          "body": "The previous devcontainer failed into recovery mode during postCreateCommand:\n- node:1 feature did not install (no node/npm/node-gyp), so better-sqlite3's\n  install (prebuild-install fails on Bun -> node-gyp fallback) exited 127\n- remoteUser: 'codespace' mismatched the actual container user (vscode)\n[…]\neUser\n- setup.sh: install build-essential/python3/pkg-config for the native-compile\n  fallback path, persist PATH to both .bashrc and .profile so login and\n  non-interactive shells find bun + opencode",
          "is_bot": false,
          "headline": "fix(ci): use node-baked-in base image + build tools in devcontainer",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T19:40:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddc2d476dbcceaae12ca7f4e795148fb640d4bdf",
          "body": "The 16-cpu/32gb hostRequirements collapsed the repo's available machine list\nto empty for this account (no 16-core tier available), blocking codespace\ncreation entirely. Without hostRequirements, GitHub falls back to the account's\ndefault machine options (2-core/4-core), which gh codespace create can use.\nMachine type can still be bumped post-creation via gh codespace edit if a\nhigher tier becomes available.",
          "is_bot": false,
          "headline": "ci: drop hostRequirements to restore default machine options",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T19:32:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "336bc023b8fd464cb2c422c821ee1d89a0b9872f",
          "body": "… bun\n\nAdds .devcontainer/devcontainer.json + setup.sh so GitHub Codespaces for this repo\nbuild a reproducible test environment for opencode-mem0 running inside opencode:\n\n- hostRequirements: 16 cpus / 32gb (max commonly-available codespace machine)\n- sshd feature: enables agent SSH via gh codespace\n[…]\norwardPorts 4096 for opencode web backend\n\nRebuild re-runs setup.sh, so tooling comes back current every time — fixes the\nstale-opencode/stale-plugin problem that occurs without a devcontainer config.",
          "is_bot": false,
          "headline": "ci: add .devcontainer for codespace test VM with current opencode and…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T19:23:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d813d0afcb3c669bf1fd5588db0af35bdd68d06",
          "body": "The awk regex '## []' used an unescaped '[' which awk treats as\na literal character-class opener. '## [2.17.1]' became '## ' + class\n[2.17.1] (any of 2,.,1,7), matching '## 7' inside '#### 7-Factor Memory\nScoring' instead of the actual '## [2.17.1]' header. This caused every\nrelease since v2.16.1 to\n[…]\nplaced the regex with index() string matching plus a boundary check so\nthe literal brackets are treated as text. Verified locally: extracts\nexactly the v2.17.1 section (and v2.17.0, v2.16.2, v2.16.1).",
          "is_bot": false,
          "headline": "fix(ci): release workflow extracted wrong changelog section",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T17:18:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14e7741c9a2b078e73dc6c4a728282e2529f2998",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 2.17.1",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T17:09:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0eac008de3ca1d17f276d0d91dcae9745ab8f4b",
          "body": "shared-types.ts (pure types), admin.ts, profile.ts, transcripts.ts\nare thin API handler wrappers with low coverage that drag the\nSonarCloud new-code gate below 80%. Excluded from both sonar-project.properties\nand vitest.config.ts coverage excludes.",
          "is_bot": false,
          "headline": "test: exclude untestable handler files from coverage gate",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T17:02:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d85d1489f94b78886815e95834a30b40f04fc839",
          "body": "…ess for solo dev\n\n- CHANGELOG.md Unreleased section: added SonarCloud Dependabot fix, CI\n  audit non-blocking, CodeRabbit removal, DeepSource config cleanup,\n  screenshots move, gitattributes cleanup, Dependabot minor/patch limit,\n  release workflow changelog extraction, CONTRIBUTING.md update, 6\n  backfilled release notes, dependency bumps (ai 7.0.4, lint-staged 17.0.8)\n- CONTRIBUTING.md: release process now says 'commits directly to main'\n  instead of 'delivered via PRs'",
          "is_bot": false,
          "headline": "docs: update changelog with post-v2.17.0 changes and fix release proc…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T16:53:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0184be8d0ac0573082f56fe7c836693b3bbfffaf",
          "body": null,
          "is_bot": false,
          "headline": "chore: restore gitignore to ignore local dev config files",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T16:49:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39596e38e17231e8d3a233c5eb1f5e49247565f6",
          "body": "The .gitignore was intentionally ignoring AGENTS.md (DOX hierarchy is\nlocal-only). PR #38 incorrectly added a !AGENTS.md exception and\nforce-added all 14 AGENTS.md files. This reverts that: removes the\nexception, untracks all AGENTS.md files from git (files stay on disk\nfor local agent use).",
          "is_bot": false,
          "headline": "fix: untrack AGENTS.md files — restore original .gitignore intent (#46)",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T16:44:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e78648054cfa41b55c3a08d71ddc51d5d1ee6215",
          "body": "Bumps [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) from 6.0.214 to 7.0.4.\n- [Release notes](https://github.com/vercel/ai/releases)\n- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)\n- [Commits](https://github.com/vercel/ai/commits/ai@7.0.4/packages/ai)\n\n---\nup\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: ZeR020 <88128532+ZeR020@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ai from 6.0.214 to 7.0.4 (#42)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-28T16:34:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f850a1230520aa0eba4296ccd055a586ea54471d",
          "body": "Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 16.4.0 to 17.0.8.\n- [Release notes](https://github.com/lint-staged/lint-staged/releases)\n- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/lint-staged/lint-staged/compar\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: ZeR020 <88128532+ZeR020@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump lint-staged from 16.4.0 to 17.0.8 (#40)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-28T16:33:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a3a772126c42b304e32d4ff73ea7bd62b0fdef5",
          "body": "…ndabot to minor/patch (#45)\n\n- SonarCloud workflow: add if guard to skip Dependabot fork PRs.\n  SONAR_TOKEN isn't available to fork PRs, causing 'Not authorized'\n  failures on all 5 Dependabot PRs (#39-#43).\n- Remove .coderabbit.yaml — CodeRabbit not needed.\n- Dependabot: restrict to semver-minor and semver-patch updates only.\n  Major bumps (TypeScript 6, @ai-sdk/openai 4) break types/APIs and\n  require manual migration.",
          "is_bot": false,
          "headline": "fix: skip SonarCloud on Dependabot PRs, remove CodeRabbit, limit Depe…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T16:30:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1dc102495e1706092fa0de1587aa184721dccaf",
          "body": "Tools:\n- CodeRabbit: assertive → chill profile, add coverage/ to path_filters,\n  instruct not to nitpick style (Prettier/DeepSource handle that) or\n  request tests for trivial one-liners, disable auto_reply\n- DeepSource: remove unnecessary react plugin (no React in project)\n- SonarCloud: add secret-\n[…]\n there)\n- Clean .gitattributes: remove dead graphify-out/ rules (directory\n  doesn't exist), add dist/coverage/lock as linguist-generated\n- Update .github/AGENTS.md and docs/AGENTS.md for moved assets",
          "is_bot": false,
          "headline": "chore: tune analysis tools to non-blocking, organize repo files (#44)",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T16:25:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec101d2bccf4a7ced2010676fc4c854176d391a9",
          "body": "…ependabot (#38)\n\n* ci: add Dependabot config and improve PR template with changelog/contributor reminders\n\n- Added .github/dependabot.yml: weekly npm dependency updates, 5 PR limit,\n  'chore' commit prefix, 'dependencies' label\n- Updated PR template: added CHANGELOG.md update checklist item, change\n[…]\nt section\n- Root AGENTS.md now documents the professional workflow:\n  no direct commits to main, PR-based delivery, squash merge,\n  Conventional Commits PR titles, release process, contributor credits",
          "is_bot": false,
          "headline": "ci: enforce PR-based workflow with branch protection, DOX tracking, D…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T16:05:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fcbad2254f8817b71708dd233f140d23ebff6a7e",
          "body": "lint-deepsource.sh: add JS-0067 (top-level function declarations in\nchanged files) and JS-R1005 (cyclomatic complexity) checks. JS-0067\nskips IIFE-wrapped files. Both only scan files changed in the current\ncommit, matching DeepSource's behavior.\n\ncheck-sonarcloud-gate.sh: new script that queries the\n[…]\n. Non-blocking (exit 0) — surfaces known failures\nwithout preventing the push.\n\npre-push hook: now runs both lint-deepsource.sh and\ncheck-sonarcloud-gate.sh so CI analysis failures are caught locally.",
          "is_bot": false,
          "headline": "ci: add local parity checks for DeepSource and SonarCloud gates",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T15:38:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f65d5f2f76ddf33eb21b0e48bddc78e9236ebce8",
          "body": "secret-resolver.test.ts: add test for statSync failure path (symlink to\nnonexistent target triggers the checkFilePermissions catch block).\n\nlogger.test.ts: new test file covering debug/warn/error log functions,\nlevel filtering, and flushLogs — these were uncovered new-code wrappers.",
          "is_bot": false,
          "headline": "test: add coverage for secret-resolver and logger to clear 80% gate",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T15:38:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cc5d1240c7e3ed712eea5e32ae88ae433a0d9cd",
          "body": "migrate-v1-to-v2.ts: wrap script body in an IIFE — DeepSource JS-0067\naccepts IIFE wrapping for module-scoped code.\n\ntags.ts: convert non-exported function declarations (sha256,\nrequireGitDirectory, getGitExecutable, execGitCommand) to const arrow\nfunctions. ESM modules are already module-scoped, but DeepSource's\nJS-0067 analyzer doesn't recognize this for `function` declarations.\nArrow function assignments are not flagged.",
          "is_bot": false,
          "headline": "fix: silence DeepSource JS-0067 false positives on changed files",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T15:38:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1f01f5b40b899ba515cdd94a1a0ffb9fad5a124",
          "body": "Document the path-traversal fix in migrate-v1-to-v2.ts, the PATH-hardening\nin tags.ts, and the coverage test additions that lift new-code coverage\nabove the 80% gate threshold.",
          "is_bot": false,
          "headline": "docs: add Unreleased changelog for SonarCloud gate fixes",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T15:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c84fb6736641f8441d315ff6d3dc91bab08aa66",
          "body": "Add tests/memory-lifecycle.test.ts (17 tests covering promoteToLTM,\nscanAndPromote, getArchivedCount, runLifecycleMaintenance, LifecycleManager\ntimer/skip logic) and extend tests/api-handlers.test.ts (handleEmbeddingCacheStats,\nhandleApiStatus → 100% coverage), tests/deduplication-service.test.ts (s\n[…]\nching, generateSummaryViaProvider/ViaOpencode,\ngetLatestProjectMemory truncation, buildMarkdownContext sections → 95.1%).\n\nNew-code coverage projected from 77.3% to ~80.2% on next SonarCloud analysis.",
          "is_bot": false,
          "headline": "test: lift SonarCloud new-code coverage above 80% gate threshold",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T15:24:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66ca3d54cfc4ff5702bedb2becb4828696a710ae",
          "body": "… hotspot)\n\nmigrate-v1-to-v2.ts: add resolveStoragePath() that resolves the CLI storage\npath to absolute and constrains it to the user's home directory, rejecting\ntraversal and out-of-home escape attempts from untrusted CLI args\n(SonarCloud tssecurity:S8707).\n\ntags.ts: remove ambient-PATH `which git` lookup; git executable now resolved\nfrom a fixed list of trusted, unwriteable locations only. Added\n/opt/homebrew/bin/git for Apple Silicon (SonarCloud typescript:S4036).",
          "is_bot": false,
          "headline": "fix: resolve SonarCloud security gate failures (path traversal + PATH…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T15:24:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f503f4a37d1812b8a3356d4125bff43a00353ca6",
          "body": "…ess to CONTRIBUTING\n\n- Added missing CHANGELOG.md entries for v2.16.0, v2.16.1, v2.16.2\n  (these releases had no changelog entries — only empty GitHub release notes)\n- Backfilled GitHub release notes for 6 releases (v2.14.0, v2.14.4,\n  v2.14.5, v2.16, v2.16.1, v2.16.2) with structured content from\n\n[…]\nbering\n  sections to CONTRIBUTING.md documenting the PR-based workflow,\n  changelog conventions, and how community contributors are credited\n- All 8 releases now have proper structured notes on GitHub",
          "is_bot": false,
          "headline": "docs: backfill changelog for v2.16.x and add release/contributor proc…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T14:15:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c7afcc5c913231b1cc109046cd4abc36f3e6367",
          "body": "- Release workflow now extracts the changelog section for the released\n  version and uses it as the GitHub release body, with auto-generated\n  notes appended (PR references, new contributors). This ensures\n  consistent, detailed release notes even when changes are applied\n  directly to main without \n[…]\n Contributors section to v2.17.0 changelog crediting @boyxil\n  (issue #34), @bob56621517 (issue #35, PR #36), and @kingrubic (PR #37).\n- Updated the v2.17.0 GitHub release with full notes and credits.",
          "is_bot": false,
          "headline": "ci: use CHANGELOG.md for release notes, add contributor credits",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T14:05:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "495c90ae38938adbd433bc8885dbc47f5881ac53",
          "body": "The 4 remaining audit findings (vite, esbuild, protobufjs) are all\ntransitive devDependencies that don't ship to users. The vite high CVE\n(server.fs.deny bypass on Windows) is a dev-server-only issue. Making\nthe audit step continue-on-error lets it report vulnerabilities without\nblocking CI on dev-only findings.",
          "is_bot": false,
          "headline": "ci: make bun audit non-blocking for dev-only vulnerabilities",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T13:58:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05000de765558dab3a3dbb761f2eb9c0e8ad0f1e",
          "body": "Version bump, changelog, and docs update for release.\n\nAdded:\n- file://~/ path expansion in *ApiKey config fields (#34)\n- initConfig() empty-config guard preserving CONFIG on transient I/O failure (#35)\n\nFixed:\n- initConfig() silent CONFIG reset to defaults (#35, #36)\n- file://~/ throws on Linux — ~\n[…]\n\n- Dynamic imports → static in auto-capture.ts and handlers/memory.ts\n- .gitignore reorganized (280 → 73 lines)\n- localStorage API key storage documented (code scanning #7)\n\nClosed: #34, #35, #36, #37",
          "is_bot": false,
          "headline": "release: v2.17.0",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T13:54:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d0cfcb9cf83412abbcef9ddfed4e1c4fa807450",
          "body": "…rage comment\n\nFour fixes from GitHub triage:\n\n- Guard initConfig() against silent CONFIG reset when both global and\n  project config sources return empty (transient I/O failure). Preserves\n  the existing CONFIG singleton instead of rebuilding from defaults.\n  Fixes #35. Closes #36, #37 (simple guar\n[…]\n Add ponytail comment on localStorage API key storage in web/app.js\n  documenting the accepted risk (localhost-only server).\n\nVerified: typecheck, 663 tests, build, format:check, deepsource lint pass.",
          "is_bot": false,
          "headline": "fix: guard initConfig reset, file://~ expansion, vitest CVE, localSto…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T13:49:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffb55d7a2e270655ac1760e4e74e322320a515f8",
          "body": "… dynamic imports\n\nThree cleanups from WIP session, plus stale-reference fixes:\n\n- Remove supportsSession() abstract method from BaseAIProvider and all 4\n  provider overrides + tests. Every implementation returned true and no\n  code branched on the result — pure dead abstraction.\n- Delete profile-ut\n[…]\ny-load benefit; removes needless async overhead.\n- Reorganize .gitignore: 280-line catch-all → 73-line categorized file.\n\nVerified: typecheck, 663 tests, build, format:check, deepsource lint all pass.",
          "is_bot": false,
          "headline": "refactor: remove dead supportsSession seam and profile-utils, convert…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T13:37:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bfd1ce43c4cc209b2bbe1cf39e2615fa8e0deeea",
          "body": "ponytail-audit execution. Removes production-unreachable code and\ncollapses abstractions with zero or one consumer:\n\n- Delete NSWBackend (nsw-backend.ts, 321 lines) + its test. The config\n  enum (VectorBackendConfig) only allows usearch-first/usearch/exact-scan;\n  nsw/nsw-first were factory-only dea\n[…]\np. Keep franc-min + iso6393To1 (3->1 mapping).\n- Inline ConflictCheckLock class as a module-level Set (single consumer).\n\nVerified: typecheck, 663 tests, build, format:check, deepsource lint all pass.",
          "is_bot": false,
          "headline": "refactor: remove dead NSW backend and collapse over-engineered seams",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-06-28T13:35:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01fefff88a7fd90b05f6f5ec748d43e7c37bb29a",
          "body": "…un:test imports)",
          "is_bot": false,
          "headline": "fix: resolve pre-existing test failures for CI (vi.doMock/vi.mocked/b…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T13:53:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e64c420b482477e9b1b094bdb41f066924c854ab",
          "body": null,
          "is_bot": false,
          "headline": "chore: add skipcq annotation for intentional plugin load console.error",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T13:46:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51d92eb650bd2ff6ee47c21dc780930c4b7e3688",
          "body": null,
          "is_bot": false,
          "headline": "chore: update bun.lock for ws >=8.20.1 advisory override",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T13:45:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e93a9088e916793b1bf8b9b709c186d2f4030884",
          "body": "…-issues\n\n- ws: override to >=8.20.1 in package.json overrides\n- plugin.ts: wrap top-level import in try/catch with error context\n- index.ts: shutdown handler cleans up globalThis symbol before running\n- auto-capture.ts: config/config errors return cleanly instead of re-throwing\n- vector-search.ts: \n[…]\n DEBUG_DECAY env var\n- Fix FallbackAwareBackend retry to use loop-based approach (prevents uncaught re-throw)\n- Update tests: cleanup getStatus includes new metrics, auto-capture config errors resolve",
          "is_bot": false,
          "headline": "feat(04-10): fix ws advisory, plugin lifecycle, and performance micro…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T11:36:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e7e0683c977457394d06b619b7d9eda2670c9fdb",
          "body": "…rics\n\n- FallbackAwareBackend: retry 3x on transient errors before switching to fallback, 60s recovery window\n- memory-scoring-service: track skippedCycles and lastDurationMs in background recalculation job\n- memory-lifecycle: track skippedCycles and lastDurationMs in background decay loop\n- cleanup-service: track skippedCycles and lastDurationMs for cleanup runs\n- handleStats: expose backgroundJobs metrics (scoring, lifecycle, cleanup)",
          "is_bot": false,
          "headline": "feat(04-10): add vector backend retry recovery and background job met…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T11:08:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f7b759738e816e38cce68c3ab4b73f1adf00771",
          "body": "…flict detection, tech debt note\n\n- S17: Promote MAX_LIST_MEMORIES/MAX_SEARCH_RESULTS/MAX_TIMELINE_ITEMS to module-level exports\n- S12: Extract duplicate existsSync(directory) guards into requireGitDirectory()\n- S20: Log duplicate ISO 639-3 codes in language-detector.ts instead of silent overwrite\n- S22: Add Known tech debt note (85+ 'as' casts) at top of config.ts",
          "is_bot": false,
          "headline": "refactor(04-09): centralize magic constants, DRY tags guards, ISO con…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T10:58:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2804bda862ced9563cb7d9d3cc5ea0ae26cf6da",
          "body": "…eck, fix config merge, simplify DEFAULTS type\n\n- S2: Remove contextTracker singleton export from retrieval-context.ts\n- S11: Fix fragile parts.length check (=== 1 -> <= 1) in context.ts\n- S13: Gate embeddingApiKey resolution on cfg.embeddingApiKey, not url\n- S18: Simplify DEFAULTS type from Required+Omit+intersection to Partial<OpenCodeMemConfig>",
          "is_bot": false,
          "headline": "fix(04-09): remove dead contextTracker export, fix context fragile ch…",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T10:53:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cc74cee0a72abe1515360b5579b26107d191311",
          "body": "- Create src/services/utils/memory-mapper.ts with canonical mapDbRow\n- Thin wrappers: mapDbRowToListItem, mapDbRowToSessionResult, mapDbRowToConflict\n- Replace rowToMemoryListItem/rowToSessionSearchResult in client.ts\n- Replace mapRawMemoryToTyped body to call mapDbRow in handlers/shared.ts\n- Replace rowToConflict with mapDbRowToConflict in memory-conflicts.ts\n- Export MemoryListItem and SessionSearchResult interfaces",
          "is_bot": false,
          "headline": "feat(04-09): centralize row-to-object mappers into memory-mapper.ts",
          "author_name": "ZeR020",
          "author_login": "ZeR020",
          "committed_at": "2026-05-30T10:47:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 20,
      "commits_last_year": 457,
      "latest_release_at": "2026-07-19T20:24:51Z",
      "latest_release_tag": "v2.18.6",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 2.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "opencode-mem0",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "opencode",
            "plugin",
            "memory",
            "vector-database",
            "ai",
            "coding-agent",
            "local",
            "standalone"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/opencode-mem0",
          "is_deprecated": false,
          "latest_version": "2.18.6",
          "repository_url": "https://github.com/ZeR020/opencode-mem0",
          "versions_count": 23,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2550,
          "first_published_at": "2026-04-30T17:05:19.807000Z",
          "latest_published_at": "2026-07-19T20:24:44.284000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 11,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-23",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 55224,
      "source_files_sampled": 141,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "adm-zip",
            "direct": false,
            "version": "0.5.18",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-xcpc-8h2w-3j85"
            ],
            "fixed_version": "0.6.0",
            "advisory_count": 1,
            "oldest_advisory_days": 15
          },
          {
            "name": "sharp",
            "direct": false,
            "version": "0.34.5",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.3,
            "advisory_ids": [
              "GHSA-f88m-g3jw-g9cj"
            ],
            "fixed_version": "0.35.0",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 2
        },
        "advisory_count": 2,
        "affected_count": 2,
        "assessed_count": 158,
        "malicious_count": 0,
        "assessed_package": "npm:opencode-mem0@2.18.6",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@ai-sdk/anthropic",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.5"
        },
        {
          "name": "@ai-sdk/openai",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.5"
        },
        {
          "name": "@huggingface/transformers",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.2.0"
        },
        {
          "name": "@opencode-ai/plugin",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.14.31"
        },
        {
          "name": "@opencode-ai/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.14.31"
        },
        {
          "name": "ai",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.4"
        },
        {
          "name": "better-sqlite3",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "franc-min",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.0"
        },
        {
          "name": "usearch",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.25.1"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@ai-sdk/anthropic",
            "direct": true,
            "version": "^4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@ai-sdk/openai",
            "direct": true,
            "version": "^4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@huggingface/transformers",
            "direct": true,
            "version": "^4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opencode-ai/plugin",
            "direct": true,
            "version": "^1.14.31",
            "ecosystem": "npm"
          },
          {
            "name": "@opencode-ai/sdk",
            "direct": true,
            "version": "^1.14.31",
            "ecosystem": "npm"
          },
          {
            "name": "ai",
            "direct": true,
            "version": "^7.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "better-sqlite3",
            "direct": true,
            "version": "^12.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "franc-min",
            "direct": true,
            "version": "^6.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "usearch",
            "direct": true,
            "version": "^2.25.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/better-sqlite3",
            "direct": false,
            "version": "^7.6.13",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bun",
            "direct": false,
            "version": "^1.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "^4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "husky",
            "direct": false,
            "version": "^9.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "lint-staged",
            "direct": false,
            "version": "^17.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "^3.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.9",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 18,
        "direct_count": 10,
        "indirect_count": 8
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 21,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 5,
        "closed_unmerged_prs": 26
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "ZeR020",
          "commits": 452,
          "avatar_url": "https://avatars.githubusercontent.com/u/88128532?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "opencode.yml",
        "release.yml",
        "sonarcloud.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e123d97946d590b87d5ca7c66f9615121d163996",
        "ran_at": "2026-07-25T20:01:12Z",
        "aggregate_score": 6.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T03:06:56Z",
      "oldest_open_prs": [
        {
          "number": 53,
          "created_at": "2026-07-23T03:06:36Z",
          "last_comment_at": "2026-07-23T03:06:53Z",
          "last_comment_author": "deepsource-io"
        }
      ],
      "last_merged_pr_at": "2026-07-04T09:47:18Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ZeR020/opencode-mem0",
    "host": "github.com",
    "name": "opencode-mem0",
    "owner": "ZeR020"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 67,
        "vitality": 76,
        "community": 53,
        "governance": 48,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 457,
              "human_commit_share": 0.97,
              "days_since_last_push": 2,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "457 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 457
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 20,
              "latest_release_tag": "v2.18.6",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 2.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "20 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 53,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "forks": 2,
              "stars": 11,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "11 stars",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "opencode-mem0"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2550
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,550 downloads/month across npm",
                "points": 45.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2550,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 21,
              "open_issues": 0,
              "closed_issues": 5,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 26
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "21/47 decided PRs merged",
                "points": 17.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 21,
                      "decided": 47
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "ZeR020",
              "public_repos": 5,
              "account_age_days": 1822
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of ZeR020",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "ZeR020"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~4 yr old",
                "points": 15.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "opencode-mem0"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "23 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai",
                "coding-agent",
                "local-first",
                "memory",
                "opencode",
                "plugin",
                "sqlite",
                "vector-database"
              ],
              "has_wiki": false,
              "homepage": "https://github.com/ZeR020/opencode-mem0",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://github.com/ZeR020/opencode-mem0",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 67,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the npm:opencode-mem0@2.18.6 runtime dependency closure — what installing the published package pulls in — 158 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:opencode-mem0@2.18.6",
                  "assessed": 158
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 84,
            "inputs": {
              "source": "osv",
              "advisories": 2,
              "affected_packages": 2,
              "assessed_packages": 158,
              "unassessed_packages": 0,
              "affected_by_severity": "high 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "2 affected: adm-zip 0.5.18 (high 7.5), sharp 0.34.5 (high 7.3)",
                "points": 8.5,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 2,
                      "packages": "adm-zip 0.5.18 (high 7.5), sharp 0.34.5 (high 7.3)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 158,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 53,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 97 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 97
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": true,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.03
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 55224,
              "source_files_sampled": 141,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/141 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 141,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T20:01:19.128197Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/z/ZeR020/opencode-mem0.svg",
  "full_name": "ZeR020/opencode-mem0",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.